2007 CVE Vulnerabilities

6,580 CVEs published in 2007.

CVE IDSeverityCVSSDescription
CVE-2007-0434BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2 does not properly set the severity l...
CVE-2007-0433Unspecified vulnerability in BEA AquaLogic Enterprise Security 2.0 through 2.0 SP2, 2.1 through 2.1 SP1, and 2.2, when u...
CVE-2007-0432BEA AquaLogic Service Bus 2.0, 2.1, and 2.5 does not properly reject malformed request messages to a proxy service, whic...
CVE-2007-0431AVM Fritz!Box 7050, and possibly other product models, allows remote attackers to cause a denial of service (VoIP applic...
CVE-2007-0430The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial ...
CVE-2007-0429DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to ...
CVE-2007-0428Unspecified vulnerability in the chtbl_lookup function in hash.c for WzdFTPD 8.0 and earlier allows remote attackers to ...
CVE-2007-0435T-Com Speedport 500V routers with firmware 1.31 allow remote attackers to bypass authentication and reconfigure the devi...
CVE-2007-0418BEA WebLogic Server 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9.1 does not enforce a security policy that decla...
CVE-2007-0417BEA WebLogic Server 7.0 through 7.0 SP7, 8.1 through 8.1 SP5, 9.0, and 9.1, when using the WebLogic Server 6.1 compatibi...
CVE-2007-0416The WSEE runtime (WS-Security runtime) in BEA WebLogic Server 9.0 and 9.1 does not verify credentials when decrypting cl...
CVE-2007-0415BEA WebLogic Server 8.1 through 8.1 SP5 does not properly enforce access control after a dynamic update and dynamic rede...
CVE-2007-0414BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, and 9.0 allows remote attackers to ca...
CVE-2007-0412BEA WebLogic Server 6.1 through 6.1 SP7, 7.0 through 7.0 SP7, and 8.1 through 8.1 SP5 allows remote attackers to read ar...
CVE-2007-0411BEA WebLogic Server 8.1 through 8.1 SP5, 9.0, 9.1, and 9.2 Gold, when WS-Security is used, does not properly validate ce...
CVE-2007-0410Unspecified vulnerability in the thread management in BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP5, 9.0, and 9....
CVE-2007-0409BEA WebLogic 7.0 through 7.0 SP6, 8.1 through 8.1 SP4, and 9.0 initial release does not encrypt passwords stored in the ...
CVE-2007-0408BEA Weblogic Server 8.1 through 8.1 SP4 does not properly validate client certificates when reusing cached connections, ...
CVE-2007-0407Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote at...
CVE-2007-0406Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_conne...
CVE-2007-0405The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests...
CVE-2007-0404bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os...
CVE-2007-0413BEA WebLogic Server 8.1 through 8.1 SP5 stores cleartext data in a backup of config.xml after offline editing, which all...
CVE-2007-0022Untrusted search path vulnerability in writeconfig in Apple Mac OS X 10.4.8 allows local users to gain privileges via a ...
CVE-2007-0021Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dere...

Check if your code is affected by 2007 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now